170 Followers
65 Following
519 Posts
First step after upgrading #DavinciResolve: Downloading AI-stuff
So CVE-2026-41089 (CVSS 9.8) in Windows Netlogon can be triggered by sending a username that is AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA or longer.
How original.

So my systems recently updated to rsync 3.4.3, and as soon as that happened my backup system - which does incremental backups using multiple --compare-dest= arguments - started to fail on anything but a full backup.

Revert to 3.4.1 and it works.

So I go look at the source in GitHub to see what might have changed, because there doesn't seem to be anything relevant in the changelog.

Since 3.4.1, 36 commits by "tridge and claude"

Oh for fuck's sakes.

On Friday the 15th of May, we became aware of a fingerprinting issue affecting Mullvad users.

We have a method which changes this behaviour currently being tested, with plans to begin rolling it out to our VPN servers in the coming weeks.

Read more here: https://mullvad.net/blog/exit-ip-fingerprinting-between-vpn-servers

Exit IP fingerprinting between VPN servers

On Friday the 15th of May, we became aware of a fingerprinting issue affecting Mullvad users.

Mullvad VPN

# PSA to Mullvad VPN Users: Mullvad Exit IP's are surprisingly identifying by tmctmt
https://tmctmt.com/posts/mullvad-exit-ips-as-a-fingerprinting-vector/

It seems that when using Mullvad VPN, exit IP's are not randomly chosen due to the use of the random_range function in the Rust backend.

The last section of the article explains the practical implications: others being able to identify you with a probability of >99%

@mullvadnet

#vpn #mullvad #opsec #networking #rust #privacy

Mullvad exit IPs as a fingerprinting vector

Mullvad is one of the few VPN providers that offers multiple exit IPs for its servers. If two people connect to the same server, they will usually end up with different public IPs. With only 578 servers (compared to Proton VPN’s 20,000), this kind of vertical scaling makes sense to avoid cramming too many users onto one IP, which would be a problem on sites with overzealous IP blocks and ratelimits.

tmctmt

Is the 'Steam Deck Controller ID' a unique ID?

For me the system-menu reports the value 12345678.

Let's Encrypt just stopped the issuance of certificates after an (so far not publicly disclosed) incident:

https://letsencrypt.status.io/pages/incident/55957a99e800baa4470002da/69fe2d6698ca07050eb4b1b3

If anyone encounters issues today with failed certificate renewals: It's probably not your setup.

Update: Let's Encrypt has resumed issuance.

#letsencrypt #itsec #devops #linux #security #tls

Let's Encrypt Status

Support for Let's Encrypt services is community-based and information on current status and outages can be found at: https://community.letsencrypt.org

If Chrome has the #optimization-guide-on-device-model and #prompt-api-for-gemini-nano flags enabled, either because it's part of some Origin Trial / Early Stable Release or something, then web pages will have access to the new Prompt API which allows any webpage to initiate the (one-time) download of the ~2.7 GiB CPU or ~4.0 GiB GPU model using LanguageModel.create()

https://news.ycombinator.com/item?id=48019542

What the f*cking hell!

If Chrome has the *#optimization-guide-on-device-model* and *#prompt-api-for-gem... | Hacker News

Gestern habe ich mein Päckchen aus China bekommen, jedoch NICHT von einem Postdienstleister.

Es war eine Privatperson.

Wieso?

Weil mein Päckchen von DHL in das Zalando-Paket besagter Privatperson gesteckt wurde. Dies wurde wohl beim Transport beschädigt und mit so einem Klebeband versehen. Wie auch immer mein Päckchen dann dort hinein kam.

Freundlicherweise hat diese Person mir mein Päckchen vorbei gebracht...

Das Tracking des Paktes? Im Verteilzentrum angekommen, aber dann nie wieder ein Update.

Der Online-Handler #Jakob behauptet, es gab ein Systemfehler. Auf der Webseite ist der Artikel dennoch "sofort verfügbar".

Ist das schon arglistige Täuschung?